CVE-2026-49740
published 2026-06-09CVE-2026-49740: TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class…
PriorityP336medium6.3CVSS 4.0
AVLACLATNPRLUINVCNVILVANSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.21%
11.9th percentile
TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store or sys_registry database table) could inject a crafted serialized payload to trigger PHP Object Injection, potentially exploiting a gadget chain to achieve Remote Code Execution or other high-impact effects. Exploiting this vulnerability requires direct local write access to the storage, such as the SQL database or file system. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms-core | >= 0 < 10.4.57 | 10.4.57 |
| typo3 | cms-core | >= 11.0.0 < 11.5.51 | 11.5.51 |
| typo3 | cms-core | >= 12.0.0 < 12.4.46 | 12.4.46 |
| typo3 | cms-core | >= 13.0.0 < 13.4.31 | 13.4.31 |
| typo3 | cms-core | >= 14.0.0 < 14.3.3 | 14.3.3 |
| typo3 | typo3_cms | < 10.4.57 | 10.4.57 |
| typo3 | typo3_cms | >= 11.0.0 < 11.5.51 | 11.5.51 |
| typo3 | typo3_cms | >= 12.0.0 < 12.4.46 | 12.4.46 |
| typo3 | typo3_cms | >= 13.0.0 < 13.4.31 | 13.4.31 |
| typo3 | typo3_cms | >= 14.0.0 < 14.3.3 | 14.3.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TYPO3 CMS up to 14.3.2 Storage Backend or deserialization (WID-SEC-2026-1835)
vuldb·2026-07-17·CVSS 6.3
CVE-2026-49740 [MEDIUM] TYPO3 CMS up to 14.3.2 Storage Backend or deserialization (WID-SEC-2026-1835)
A vulnerability was found in TYPO3 CMS up to 10.4.56/11.5.50/12.4.45/13.4.30/14.3.2 and classified as problematic. This affects the function or of the component Storage Backend. The manipulation results in deserialization.
This vulnerability is reported as CVE-2026-49740. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
TYPO3 CMS has Insecure Deserialization via Core API
ghsa·2026-06-12
CVE-2026-49740 [MEDIUM] CWE-502 TYPO3 CMS has Insecure Deserialization via Core API
TYPO3 CMS has Insecure Deserialization via Core API
### Problem
TYPO3's cache frontend (`VariableFrontend`) and persistent key-value store (`Registry`) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store or sys_registry database table) could inject a crafted serialized payload to trigger PHP Object Injection, potentially exploiting a gadget chain to achieve Remote Code Execution or other high-impact effects.
Exploiting this vulnerability requires direct local write access to the storage, such as the SQL database or file system.
### Solution
Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
### Credits
TYPO3 CMS t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published